Exploitable Authentication Flaw in Ghost CMS by TryGhost
CVE-2026-105676
4.9MEDIUM
What is CVE-2026-105676?
A vulnerability in Ghost, a popular Node.js-based content management system, has been identified in how it handles theme translation files. This flaw allows an authenticated Administrator to access and read JSON files located outside the active theme's directory. The exposed files may contain sensitive information, including server configuration secrets, which poses a security risk. The issue has been addressed and mitigated in version 6.64.0 of Ghost.
Affected Version(s)
Ghost >= 1.20.0, < 6.64.0
